CVE-2022-49385

high

Description

In the Linux kernel, the following vulnerability has been resolved: driver: base: fix UAF when driver_attach failed When driver_attach(drv); failed, the driver_private will be freed. But it has been added to the bus, which caused a UAF. To fix it, we need to delete it from the bus when failed.

References

https://git.kernel.org/stable/c/cdf1a683a01583bca4b618dd16223cbd6e462e21

https://git.kernel.org/stable/c/c059665c84feab46b7173d3a1bf36c2fb7f9df86

https://git.kernel.org/stable/c/823f24f2e329babd0330200d0b74882516fe57f4

https://git.kernel.org/stable/c/5d709f58c743166fe1c6914b9de0ae8868600d9b

https://git.kernel.org/stable/c/5389101257828d1913d713d9a40acbe14f5961df

https://git.kernel.org/stable/c/310862e574001a97ad02272bac0fd13f75f42a27

Details

Source: Mitre, NVD

Published: 2025-02-26

Updated: 2025-03-25

Risk Information

CVSS v2

Base Score: 4.6

Vector: CVSS2#AV:L/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00039